Junglewise Threat Intelligence

CVE-2022-34749: PYSEC-2022-237 - In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtrackin

CVE-2022-34749 · Severity: low · CVSS 3.1 · Published 2022-07-25

Technologies: mistune (PyPI). Vendors: PyPI.

Executive brief

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

Affected products

  • PyPI mistune

Related threats